CVE-2013-1048
published 2013-03-06CVE-2013-1048: The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP…
PriorityP417medium4.6CVSS 2.0
AVLACLAuNCPIPAP
EPSS
0.38%
30.0th percentile
The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | apache2 | < apache2 2.2.22-13 (bookworm) | apache2 2.2.22-13 (bookworm) |
| debian | apache2 | <= 2.2.16-6 | — |
| debian | apache2 | <= 2.2.22-12 | — |
| debian | apache2 | >= 0 < 2.2.22-13 | 2.2.22-13 |
| debian | apache2 | >= 0 < 2.2.22-13 | 2.2.22-13 |
| debian | apache2 | >= 0 < 2.2.22-13 | 2.2.22-13 |
| debian | apache2 | >= 0 < 2.2.22-13 | 2.2.22-13 |
CVSS provenance
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv4.6MEDIUM
vendor_debian4.6MEDIUM
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2013-03-18·CVSS 4.3
CVE-2012-3499 [MEDIUM] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in the Apache HTTP Server.
Niels Heinen discovered that multiple modules incorrectly sanitized certain
strings, which could result in browsers becoming vulnerable to cross-site
scripting attacks when processing the output. With cross-site scripting
vulnerabilities, if a user were tricked into viewing server output during a
crafted server request, a remote attacker could exploit this to modify the
contents, or steal confidential data (such as passwords), within the same
domain. (CVE-2012-3499, CVE-2012-4558)
It was discovered that the mod_proxy_ajp module incorrectly handled error
states. A remote attacker could use this issue to cause the server to stop
responding, resulting in a denial of service. Thi
Debian
CVE-2013-1048: apache2 - The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+sque...
vendor_debian·2013·CVSS 4.6
CVE-2013-1048 [MEDIUM] CVE-2013-1048: apache2 - The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+sque...
The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
Scope: local
bookworm: resolved (fixed in 2.2.22-13)
bullseye: resolved (fixed in 2.2.22-13)
forky: resolved (fixed in 2.2.22-13)
sid: resolved (fixed in 2.2.22-13)
trixie: resolved (fixed in 2.2.22-13)
GHSA
GHSA-xvpr-22g7-3fc2: The Debian apache2ctl script in the apache2 package squeeze before 2
ghsa_unreviewed·2022-05-17
CVE-2013-1048 [MEDIUM] GHSA-xvpr-22g7-3fc2: The Debian apache2ctl script in the apache2 package squeeze before 2
The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
OSV
CVE-2013-1048: The Debian apache2ctl script in the apache2 package squeeze before 2
osv·2013-03-06·CVSS 4.6
CVE-2013-1048 [MEDIUM] CVE-2013-1048: The Debian apache2ctl script in the apache2 package squeeze before 2
The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2013-03-06
Published